Source: glibc
Version: 2.42-14
Severity: important
Tags: security upstream
Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=33980
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glibc.

CVE-2026-4046[0]:
| The iconv() function in the GNU C Library versions 2.43 and earlier
| may crash due to an assertion failure when converting inputs from
| the IBM1390 or IBM1399 character sets, which may be used to remotely
| crash an application.    This vulnerability can be trivially
| mitigated by removing the IBM1390 and IBM1399 character sets from
| systems that do not need them.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-4046
    https://www.cve.org/CVERecord?id=CVE-2026-4046
[1] https://sourceware.org/bugzilla/show_bug.cgi?id=33980
[2] 
https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to